📦 Ollama

by Ollama

🔍 What is Ollama?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-63389

CRITICAL CVSS 9.8 Dec 18, 2025

A critical authentication bypass vulnerability in Ollama platform allows remote attackers to perform unauthorized model management operations without authentication. This affects all Ollama installati...

CVE-2025-66959

HIGH CVSS 7.5 Jan 21, 2026

A vulnerability in ollama's GGUF decoder allows remote attackers to trigger a denial of service by sending specially crafted input. This affects all systems running vulnerable versions of ollama that ...

CVE-2025-66960

HIGH CVSS 7.5 Jan 21, 2026

A vulnerability in ollama v0.12.10 allows remote attackers to cause denial of service by sending specially crafted GGUF files. The readGGUFV1String function fails to properly validate string length va...

CVE-2025-0312

HIGH CVSS 7.5 Mar 20, 2025

A null pointer dereference vulnerability in Ollama versions up to 0.3.14 allows attackers to upload specially crafted GGUF model files that crash the server, causing denial of service. This affects al...

CVE-2025-0315

HIGH CVSS 7.5 Mar 20, 2025

A memory exhaustion vulnerability in Ollama allows attackers to upload specially crafted GGUF model files that cause unlimited memory allocation, leading to Denial of Service. This affects all Ollama ...

CVE-2025-0317

HIGH CVSS 7.5 Mar 20, 2025

A vulnerability in Ollama versions up to 0.3.14 allows attackers to upload malicious GGUF model files that trigger a division by zero error, causing server crashes and denial of service. This affects ...

CVE-2024-8063

HIGH CVSS 7.5 Mar 20, 2025

A divide-by-zero vulnerability in ollama/ollama v0.3.3 allows attackers to cause denial of service by importing malicious GGUF models with crafted block_count values. This affects anyone running vulne...

CVE-2024-12055

HIGH CVSS 7.5 Mar 20, 2025

A vulnerability in Ollama versions up to 0.3.14 allows attackers to upload specially crafted gguf model files that cause an out-of-bounds read, crashing the server and creating a Denial of Service con...

CVE-2024-39722

HIGH CVSS 7.5 Oct 31, 2024

This vulnerability in Ollama allows attackers to discover which files exist on the server via path traversal in the api/push route. It affects all deployments of Ollama versions before 0.1.46. This in...

CVE-2024-39720

HIGH CVSS 8.2 Oct 31, 2024

This vulnerability allows attackers to crash Ollama servers by uploading a specially crafted GGUF file and triggering a segmentation fault through the CreateModel route. All Ollama instances running v...

CVE-2024-37032

HIGH CVSS 8.8 May 31, 2024

This vulnerability in Ollama allows attackers to bypass path validation when retrieving model files, potentially leading to arbitrary file read or remote code execution. It affects all Ollama installa...

CVE-2025-44779

MEDIUM CVSS 6.6 Aug 7, 2025

This vulnerability in Ollama v0.1.33 allows attackers to delete arbitrary files by sending a specially crafted packet to the /api/pull endpoint. It affects systems running vulnerable versions of Ollam...